CVE-2026-88774
HIGH(7.2)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- CVSS 7.2 — Hoch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.2
Technische Schwere
Beschreibung
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Erkennung & Indikatoren
Ausnutzung
In den geprüften Quellen nicht genannt
Behobene Versionen
- 14.1-73.37
- 13.1-64.23
- 14.1-73.37 FIPS
- 13.1.37.279
- 13.1-64.23
- 14.1-73.37
Threat-Hunting-Queries
Detection for feature policy bypass via HTTP URL-based expression usage. This query looks for unusual HTTP URL patterns or policy bypass attempts.
Sentinel/Defender KQL
DeviceNetworkEvents
| where InitiatingProcessFileName =~ "httpd" or InitiatingProcessFileName =~ "nginx"
| where RemoteUrl contains "..%2f" or RemoteUrl contains "%2e%2e%2f" or RemoteUrl contains "/etc/passwd" or RemoteUrl contains "/proc/self/cmdline"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteUrl, RemoteIPSplunk SPL
(sourcetype=access_combined OR sourcetype=nginx:access) (uri_path="%2e%2e%2f" OR uri_path="..%2f" OR uri_path="/etc/passwd" OR uri_path="/proc/self/cmdline")
| table _time, host, uri_path, clientipSigma
title: Citrix NetScaler Feature Policy Bypass Attempt
status: experimental
description: Detects attempts to bypass feature policies in Citrix NetScaler ADC/Gateway via HTTP URL-based expressions.
logsource:
category: webserver
service: access_log
detection:
selection:
cve_2026_88774_indicators:
- url|contains: ['..%2f', '%2e%2e%2f', '/etc/passwd', '/proc/self/cmdline']
condition: selection
fields:
- client_ip
- url
- user_agent
level: mediumElastic ES|QL
FROM logs-webserver-*-*
| WHERE url.path : ("*%2e%2e%2f*", "*..%2f*", "*/etc/passwd*", "*/proc/self/cmdline*")
| SELECT @timestamp, host.name, url.original, source.ipSecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- https://cert.europa.eu/publications/security-advisories/2026-014/
- https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*